
Research
/Security News
Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets
Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.
@namch/agent-assistant
Advanced tools
Multi-agent orchestration framework for AI coding assistants (Cursor, Copilot, Antigravity, Claude Code) with Hybrid Skill Orchestration Layer (HSOL).
Multi-agent orchestration for AI coding assistants
Transform one AI into a coordinated team of 21 specialist agents with structured workflows and 310+ domain skills.
| 🎯 Feature | What It Does |
|---|---|
| One-Time Setup, Forever Use | Configure once at global level (~/.cursor/, ~/.claude/, etc.) and it auto-applies to ALL your projects. No more repetitive config for every new repo. |
| Sub-Agent Orchestration | When supported (Claude Code, Cursor Max mode), the main agent spawns specialized sub-agents to handle tasks in parallel — backend, frontend, testing, security all working simultaneously. |
| Multi-Platform Support | Works seamlessly across Cursor, GitHub Copilot, Claude Code, and Antigravity/Gemini. Same workflows, any tool. |
| Matrix Skill Discovery (HSOL) | Injects the right skills by profile and request; optional dynamic discovery (find-skills) for hard/focus when matrix fitness < 0.8. 310+ matrix skills, zero manual config. |
Code less, deliver more. Reduce token costs by 85%, cut bugs by 70%, and stop wasting time on repetitive tasks.
| Metric | Improvement |
|---|---|
| ⏰ Time-to-Production | 70% faster |
| 🐛 Bug Rate | 70% reduction |
| 💰 Token Cost | 85% savings |
npm install -g @namch/agent-assistant
# After installing globally, run:
agent-assistant install cursor # Setup for Cursor
agent-assistant install claude # Setup for Claude Code
agent-assistant install copilot # Setup for GitHub Copilot
agent-assistant install antigravity # Setup for Antigravity/Gemini
agent-assistant install --all # Setup for ALL tools
# Clone
git clone https://github.com/hainamchung/agent-assistant.git
cd agent-assistant
# Install for your tool(s)
node cli/install.js install cursor # Cursor
node cli/install.js install claude # Claude Code
node cli/install.js install copilot # GitHub Copilot
node cli/install.js install antigravity # Antigravity/Gemini
node cli/install.js install --all # All tools
That's it. The framework installs globally and works across all your projects.
agent-assistant uninstall cursor # Remove from Cursor
agent-assistant uninstall claude # Remove from Claude Code
agent-assistant uninstall copilot # Remove from GitHub Copilot
agent-assistant uninstall antigravity # Remove from Antigravity/Gemini
agent-assistant uninstall --all # Remove from ALL tools
npm uninstall -g @namch/agent-assistant
cd agent-assistant
node cli/install.js uninstall cursor # Remove from Cursor
node cli/install.js uninstall claude # Remove from Claude Code
node cli/install.js uninstall copilot # Remove from GitHub Copilot
node cli/install.js uninstall antigravity # Remove from Antigravity/Gemini
node cli/install.js uninstall --all # Remove from all tools
# Then remove the directory
cd ..
rm -rf agent-assistant
/docs:core # Technical docs for AI context
/docs:business # Business requirements
Creates ./documents/ files that agents reference. Without docs, agents work generically. With docs, they follow YOUR patterns.
/cook:fast "add dark mode toggle" # Simple feature
/cook:hard "implement OAuth 2.0" # Complex feature with all quality gates
/fix "payment fails on Safari" # Bug fix
/plan "build notification system" # Implementation plan
/test:hard "user registration flow" # Generate tests
/review "audit auth module" # Code review
/report "status report for sprint" # Reporting (create/update reports)
| Variant | Use For | Agents |
|---|---|---|
:fast | Simple tasks | 2-3 agents |
:hard | Complex features | 5-8 agents + quality gates |
:focus | Clean execution | Clear context + auto-run phases (cook, code, fix, debug, design, plan, test, report) |
:hard and :focus are designed to reduce context rot (the model drifting or "hallucinating" from long chat history):
:hard: Structured workflow (phases + deliverables) so each step is grounded in your input + prior phase output, not arbitrary chat history.:focus: Clear context before running—execution starts "clean" for your request; phases run in order without pulling in old conversation.Use :focus when you want execution to stick strictly to the current request (e.g. large refactors, tricky bugs, or after a long chat). More stable results, less "history hallucination".
| Category | Commands |
|---|---|
| Build | /cook, /code, /fix |
| Quality | /test, /review, /debug |
| Plan | /plan, /brainstorm, /design |
| Docs | /docs:core, /docs:business, /docs:audit |
| Report | /report:fast, /report:hard, /report:focus |
| Deploy | /deploy:check, /deploy:preview, /deploy:production |
| Domain | Agents |
|---|---|
| Implementation | backend-engineer, frontend-engineer, mobile-engineer, game-engineer |
| Architecture | tech-lead, database-architect |
| Quality | tester, reviewer, debugger, security-engineer |
| Planning | planner, brainstormer, business-analyst |
| Support | designer, devops-engineer, docs-manager, performance-engineer, researcher, scouter, project-manager, reporter |
Agents don't have hardcoded skills. They declare a profile, and the Matrix automatically injects relevant skills:
# Agent declares:
profile: "backend:execution"
# Matrix resolves → 20+ backend skills injected automatically
310+ skills across 19 domains. Add a new skill once, all relevant agents get it instantly.
agent-assistant/
├── agents/ # 21 specialist agents
├── commands/ # 50+ workflow commands (routers + variants: fast, hard, focus)
├── rules/ # 8 orchestration rules
├── matrix-skills/ # 19 domain skill registries
├── skills/ # 310+ domain skills
└── cli/ # Installer
| Tool | Status | Install Path |
|---|---|---|
| Cursor | ✅ Full | ~/.cursor/ |
| Claude Code | ✅ Full | ~/.claude/ |
| GitHub Copilot | ✅ Full | ~/.copilot/ |
| Antigravity | ✅ Full | ~/.gemini/ |
feat:, fix:, docs:) → PRIf this helps you ship faster, consider buying me a coffee!
Agent Assistant — Code less. Deliver more.
FAQs
Multi-agent orchestration framework for AI coding assistants (Cursor, Copilot, Antigravity, Claude Code, Codex) with Hybrid Skill Orchestration Layer (HSOL).
The npm package @namch/agent-assistant receives a total of 45 weekly downloads. As such, @namch/agent-assistant popularity was classified as not popular.
We found that @namch/agent-assistant demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.

Security News
ENISA’s new package manager advisory outlines the dependency security practices companies will need to demonstrate as the EU’s Cyber Resilience Act begins enforcing software supply chain requirements.

Research
/Security News
We identified over 20 additional malicious extensions, along with over 20 related sleeper extensions, some of which have already been weaponized.